﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 4648 - A logon was attempted using explicit credentials  / Failure events for 4648 / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 17 May 2012 08:43:34 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Failure events for 4648</title><link>http://forum.ultimatewindowssecurity.com/Topic309-172-1.aspx</link><description>We are looking for a failed version of this event.  Your example is a succesful</description><pubDate>Wed, 08 Sep 2010 05:20:38 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>RE: Failure events for 4648</title><link>http://forum.ultimatewindowssecurity.com/Topic309-172-1.aspx</link><description>Source:        Microsoft-Windows-Security-Auditing&lt;br&gt;Date:          8/9/2010 6:37:13 PM&lt;br&gt;Event ID:      4648&lt;br&gt;Task Category: Logon&lt;br&gt;Level:         Information&lt;br&gt;Keywords:      Audit Success&lt;br&gt;User:          N/A&lt;br&gt;Computer:      Computer_name&lt;br&gt;Description:&lt;br&gt;A logon was attempted using explicit credentials.&lt;br&gt;&lt;br&gt;Subject:&lt;br&gt;	Security ID:		SYSTEM&lt;br&gt;	Account Name:		Computer_Name$&lt;br&gt;	Account Domain:		WORKGROUP&lt;br&gt;	Logon ID:		0x3e7&lt;br&gt;	Logon GUID:		{00000000-0000-0000-0000-000000000000}&lt;br&gt;&lt;br&gt;Account Whose Credentials Were Used:&lt;br&gt;	Account Name:		SYSTEM&lt;br&gt;	Account Domain:		NT AUTHORITY&lt;br&gt;	Logon GUID:		{00000000-0000-0000-0000-000000000000}&lt;br&gt;&lt;br&gt;Target Server:&lt;br&gt;	Target Server Name:	localhost&lt;br&gt;	Additional Information:	localhost&lt;br&gt;&lt;br&gt;Process Information:&lt;br&gt;	Process ID:		0x2e8&lt;br&gt;	Process Name:		C:\Windows\System32\services.exe&lt;br&gt;&lt;br&gt;Network Information:&lt;br&gt;	Network Address:	-&lt;br&gt;	Port:			-&lt;br&gt;&lt;br&gt;This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.&lt;br&gt;&lt;br&gt;[b]&lt;br&gt;This is a copy of Security Event Log from my laptop (I changed only the original name of computer to Computer_Name, and Account Name which appears as computer name too to Computer_Name). Can you post an explanations to Event ID:4648.[/b]</description><pubDate>Tue, 07 Sep 2010 21:03:55 GMT</pubDate><dc:creator>SecShield</dc:creator></item><item><title>RE: Failure events for 4648</title><link>http://forum.ultimatewindowssecurity.com/Topic309-172-1.aspx</link><description>Look for failed 4625 - My testing indicates that Windows does not log failed 4668.  If anyone produces one please send me a copy of the event and the steps to recreate.</description><pubDate>Wed, 17 Feb 2010 09:08:42 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>RE: Failure events for 4648</title><link>http://forum.ultimatewindowssecurity.com/Topic309-172-1.aspx</link><description>Sorry make that 4648.</description><pubDate>Tue, 16 Feb 2010 10:28:14 GMT</pubDate><dc:creator>mdstevens</dc:creator></item><item><title>Failure events for 4648</title><link>http://forum.ultimatewindowssecurity.com/Topic309-172-1.aspx</link><description>Hi I am looking for the failure events for 4638 events (RunAs) any ideas where this lives in 2008?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mark</description><pubDate>Tue, 16 Feb 2010 10:27:11 GMT</pubDate><dc:creator>mdstevens</dc:creator></item></channel></rss>
